Daggerfly

MITRE ATT&CK: G1034 View on attack.mitre.org

Aliases: Evasive Panda, BRONZE HIGHLAND, Daggerfly, Daggerfly

First seen
2012-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
17 (3 malicious)
Last IoC activity
2026-08-02 15:55:12
Profile updated
2026-07-07 12:02:36

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:cn country_code:in country_code:ke

Context

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to Daggerfly (G1034). The 3 most recently updated:

TypeIndicatorUpdatedSources
file sample Snipaste.exe 2026-08-02 2
file sample audio 2025-10-21 2
file sample clipboard capture 2025-08-31 2

Detection coverage

  • 16 YARA rules
  • 537 Sigma rules

Malware & tools used

  • Code Signing Certificates (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Web Protocols (attack-pattern)
  • PowerShell (attack-pattern)
  • Rename Legitimate Utilities (attack-pattern)
  • Malicious Link (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Compromise Software Supply Chain (attack-pattern)
  • DLL (attack-pattern)
  • Rundll32 (attack-pattern)
  • Server (attack-pattern)
  • Local Account (attack-pattern)
  • Code Signing (attack-pattern)
  • Query Registry (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Nightdoor (malware)
  • BITSAdmin (malware)
  • PlugX (malware)
  • MgBot (malware)
  • MacMa (malware)
  • Reg (malware)

Reports & references

  • blog.malwarebytes.com — Chinese Apt Group Targets India And Hong Kong Using New Variant Of Mgbot Malware (report)
  • vb2020.vblocalhost.com — Vb2020 43 (report)
  • youtube.com — Watch (report)
  • ESET — Evasive Panda Apt Group Malware Updates Popular Chinese Software (report)
  • virusbulletin.com — Needle Haystack (report)
  • MITRE ATT&CK — G1034 (report)
  • Broadcom/Symantec — Apt Attacks Telecoms Africa Mgbot (report)
  • Broadcom/Symantec — Daggerfly Espionage Updated Toolset (report)
  • ESET — Evasive Panda Leverages Monlam Festival Target Tibetans (report)

External references